Unmanned Aerial Vehicle Beyond Visual Line of Sight Control
Abstract
Methods, systems and apparatus, including computer programs encoded on computer storage media for unmanned aerial vehicle beyond visual line of sight (BVLOS) flight operations. In an embodiment, a flight planning system of an unmanned aerial vehicle (UAV) can identify handoff zones along a UAV flight corridor for transferring control of the UAV between ground control stations. The start of the handoff zones can be determined prior to a flight or while the UAV is in flight. For handoff zones determined prior to flight, the flight planning system can identify suitable locations to place a ground control station (GCS). The handoff zone can be based on a threshold visual line of sight range between a controlling GCS and the UAV. For determining handoff zones while in flight, the UAV can monitor RF signals from each GCS participating in the handoff to determine the start of a handoff period.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A computer-implemented method performed by an unmanned aerial vehicle (UAV), comprising:
receiving radio-frequency signals respectively from a first ground control station (GCS1) and a second ground control station (GCS2) while the UAV is under operative control of GCS1; predicting, from characteristics of the radio-frequency signals, a future start time of a handoff period for transferring operative control from GCS1 to GCS2; prior to the predicted start time, authenticating GCS2 using cryptographic credentials provisioned by a trusted service and synchronizing, with GCS2, a flight plan that is digitally signed; at the predicted start time, determining that the handoff period has begun; during the handoff period, transferring operative control of the UAV from GCS1 to GCS2; and recording, in a log stored on the UAV, acknowledgments from GCS1 and GCS2 that confirm completion of the transfer of operative control, the log maintaining attempt counters for a plurality of handoff sub-steps including authentication and flight-plan synchronization.
22 . The method of claim 21 , wherein authenticating GCS2 comprises at least one of public-key cryptography (PKC), elliptic-curve cryptography (ECC), or a certificate-less signcryption tag key encapsulation mechanism (eCLSC-TKEM).
23 . The method of claim 21 , wherein the trusted service provides private keys to authorized ground-control operators using a symmetric-key-based scheme for authentication.
24 . The method of claim 21 , wherein synchronizing the flight plan comprises transmitting delta updates from the UAV to GCS2 and verifying a digital signature of the flight plan prior to granting operative control to GCS2.
25 . The method of claim 21 , further comprising:
prior to the predicted start time, exchanging freshness information including nonces and message counters with GCS2 and rejecting replayed messages during the handoff period based on the freshness information.
26 . The method of claim 21 , further comprising:
computing a duration of the handoff period from a time budget that includes sub-steps of link establishment, authentication, flight-plan synchronization, control transfer, and acknowledgments, the time budget including configured retry counts for one or more sub-steps and the attempt counters being incremented upon each retry.
27 . The method of claim 21 , further comprising:
when retries for a sub-step are exhausted without success,
executing a contingency flight action comprising at least one of loitering,
returning to home,
changing altitude within a constraint of the flight plan, or
altering the flight path without violating a geofence boundary.
28 . A system comprising:
a UAV having one or more processors and memory storing instructions; a first ground control station (GCS1) communicatively coupled to the UAV; a second ground control station (GCS2) communicatively couplable to the UAV; and a trusted service configured to provision cryptographic credentials, wherein the instructions, when executed by the one or more processors, cause the UAV to:
predict, from radio-frequency measurements, a future start time of a handoff period for transferring operative control from GCS1 to GCS2;
authenticate, prior to the predicted start time, GCS2 using credentials provisioned by the trusted service and synchronize, with GCS2, a digitally-signed flight plan;
transfer, during the handoff period, operative control from GCS1 to GCS2; and
store, in non-transitory memory, acknowledgments from GCS1 and GCS2 confirming completion of the transfer of operative control together with attempt counts for handoff sub-steps.
29 . The system of claim 28 , wherein the trusted service provisions private keys to authorized ground-control operators using a symmetric-key-based scheme for authentication.
30 . The system of claim 28 , wherein authenticating GCS2 uses at least one of PKC, ECC, or eCLSC-TKEM.
31 . The system of claim 28 , wherein the UAV computes a duration of the handoff period from a time budget that includes sub-steps of link establishment, authentication, flight-plan synchronization, control transfer, and acknowledgments, and sizes the handoff period based on the computed duration.
32 . The system of claim 28 , wherein the UAV gates relinquishment of control by GCS1 until authentication of GCS2 is successful and the digitally-signed flight plan is synchronized with GCS2.
33 . The system of claim 28 , wherein the acknowledgments and the attempt counts are recorded with timestamps in a log maintained by the UAV.
34 . The system of claim 28 , wherein synchronizing the digitally-signed flight plan comprises verifying a digital signature on the flight plan at GCS2 prior to granting operative control to GCS2.
35 . The system of claim 28 , wherein the instructions further cause the UAV to:
upon failure of a handoff sub-step after exhausting retries, execute a contingency flight action comprising at least one of loitering, returning to home, changing altitude within a constraint of the flight plan, or altering the flight path without violating a geofence boundary.
36 . An apparatus comprising:
one or more non-transitory computer-readable medium; and instructions stored on the one or more non-transitory computer-readable medium that, when executed by one or more processors of a UAV, cause the UAV to: receive radio-frequency signals respectively from a first ground control station (GCS1) and a second ground control station (GCS2) while the UAV is under operative control of GCS1; predict a future start time of a handoff period for transferring operative control from GCS1 to GCS2; prior to the predicted start time, authenticate GCS2 using cryptographic credentials provisioned by a trusted service and synchronizing, with GCS2, a flight plan that is digitally signed; during the handoff period, transfer operative control from GCS1 to GCS2; and log acknowledgments from GCS1 and GCS2 confirming completion of the transfer of operative control and maintaining attempt counters for handoff sub-steps.
37 . The apparatus of claim 36 , wherein authenticating GCS2 comprises at least one of PKC, ECC, or eCLSC-TKEM.
38 . The apparatus of claim 36 , wherein the instructions, when executed by the one or more processors of the UAV, further cause the UAV to:
obtain, from the trusted service, private keys for authorized ground-control operators using a symmetric-key-based scheme for authentication.
39 . The apparatus of claim 36 , wherein the instructions, when executed by the one or more processors of the UAV, further cause the UAV to:
further cause the UAV to compute a duration of the handoff period from a time budget that includes sub-steps of link establishment, authentication, flight-plan synchronization, control transfer, and acknowledgments, with configured retry counts for one or more sub-steps.
40 . The apparatus of claim 36 , wherein the instructions, when executed by the one or more processors of the UAV, further cause the UAV to:
execute a contingency flight action when retries for a handoff sub-step are exhausted without success.Join the waitlist — get patent alerts
Track US2026028119A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.